Rule ID
SV-285238r1258664_rule
Version
V1R1
CCIs
To prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e., embedding of data types within data types), organizations must disable or restrict unused or unnecessary physical and logical ports/protocols on information systems. Infoblox systems provide DNS, Dynamic Host Configuration Protocol (DHCP), and IP Address Management (DDI) services. Some of the functions and services provided may not be necessary to support essential organizational operations. Additionally, it is sometimes convenient to provide multiple services from a single component (e.g., DNS and DHCP); however, doing so increases risk over limiting the services provided by any one component. This risk may be increased depending on placement in the network. Internal systems often provide DNS and DHCP; however, external systems or those in a DMZ provide only DNS. Satisfies: SRG-APP-000142-DNS-000014, SRG-APP-000383-DNS-000109, SRG-APP-000516-DNS-000500
Verify Infoblox is configured to prohibit or restrict unapproved ports and protocols. By default, all services other than those required for management are disabled. Validate that no additional services have been configured for DNS members. 1. Navigate to Infoblox Grid >> Grid Manager >> or to System >> System Manager >> System Properties if using a stand-alone configuration. 2. Select the "Services" tab and review each service at the top of the panel and "Service Status" for each member. Depending on purchased options, Infoblox DNS service members may be running DNS and optionally running services supporting DNS and security operations such as DNS Traffic Control, Threat Defense, Threat Analytics, and TAXII services. Use of these additional Infoblox services is not a finding. If any unnecessary services such as file distribution services are enabled on the DNS members, this is a finding. Note: DNSSEC is intended for third-party authenticity determination. Attempting to utilize DNSSEC internally was never an intended use case as it would require every consumer to have a third-party validating resolver installed along with a mechanism for periodic trust anchor distribution/update.
1. Navigate to Infoblox Grid >> Grid Manager or to System >> System Manager >> System Properties if using a stand-alone configuration. 2. Select the "Services" tab. 3. Select each available service at the top of the panel and review the service status. 4. Click on the member and disable unnecessary services.